Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by cipher, Sep 25, 2009.

  1. cipher

    cipher Major Geek Extraordinaire

    I've recently installed a new copy of XP SP3, activated, and installed my anti-virus, spybot etc.

    Sometime the first day, 3 porn site browser shortcuts appeared on my desktop, I deleted them. I cannot access microsoft sites or most AV sites.

    I started on your removal instructions and got this far:

    Viewpoint Media Player uninstalled.
    Cannot install jre-6u16-windows-i586, double click, click Run, nothing happens.
    Downlaoded the apps and lauched SUPERAntiSpyware
    Cannot find msconfig is preventing that install.

    Also, If I try to open Avira, I get:

    The application module
    c:\program files\avira\antivir desktop\avcenter.exe
    cannot be found or has been modified or destroyed.
    The AVCENTER.EXE cannot be started.
    please check your installation

    I am committed to following your instructions to the letter, but am having some trouble as you can see. Any help appreciated...
     
  2. cipher

    cipher Major Geek Extraordinaire

    OK, been thru the readme steps

    Viewpoint Media Player uninstalled.
    Cannot install jre-6u16-windows-i586, double click, click Run, nothing happens.
    Cannot find msconfig


    Combo fix gave warning about virus, this copy may be patched/corrupted by Virut.

    could not access http://www.microsoft.com/Downloads/...E3-F589-4842-8157-034D1E7CF3A3&displaylang=en to download .NET Framework

    Couldn't get the RRlog to attach, as txt or rich text...
     
    Last edited: Jul 26, 2012
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry to give you the bad news but ComboFix was correct. You will have to do a total clean reinstall.

    I can see the reason for your problems. Your logs show that your Windows Operating system files have become infected by a Virut infection and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possibly become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected. Anything you may have already backed up that is an executable type file (things you downloaded to install programs....etc) are most likely infected and will cause you to be reinfected if you reuse these files.

    Once you backup, you need to format partitions and reinstall Windows and all other software especially your protection software. Then install all updates for all software. DO NOT reinstall from any executable file backups you made while this PC was infected or you will just be reinstalling the infection.
     
  4. cipher

    cipher Major Geek Extraordinaire

    Thanks, your time is appreciated. I followed your advice, including rewriting the MBR, deleting partition and rebuilding it.

    All is well now.

    Advice to anyone reading this: Backup your files. Saved me a lot of heartache...
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds